CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12158
5.3 MEDIUM

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Jan 7, 2025
CVE-2024-12157
7.5 HIGH

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'upc_delete_db_record' AJAX action …

Jan 7, 2025
CVE-2024-12153
6.1 MEDIUM

The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Jan 7, 2025
CVE-2024-12140
4.3 MEDIUM

The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to Information Exposure in all versions up to, …

Jan 7, 2025
CVE-2024-12126
6.1 MEDIUM

The SEO Keywords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘google_error’ parameter in all versions up to, and including, 1.1.3 due …

Jan 7, 2025
CVE-2024-12049
6.1 MEDIUM

The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd' parameters in all versions up to, and …

Jan 7, 2025
CVE-2024-11810
6.1 MEDIUM

The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' parameter in all versions up to, and including, 1.0.26 …

Jan 7, 2025
CVE-2024-11690
6.1 MEDIUM

The Financial Stocks & Crypto Market Data Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'e' parameter in all versions up …

Jan 7, 2025
CVE-2024-11496
6.5 MEDIUM

The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all …

Jan 7, 2025
CVE-2024-11465
7.2 HIGH

The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization …

Jan 7, 2025
CVE-2024-11445
6.4 MEDIUM

The Image Magnify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_magnify' shortcode in all versions up to, and including, 1.1 …

Jan 7, 2025
CVE-2024-11434
6.1 MEDIUM

The WP – Bulk SMS – by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up …

Jan 7, 2025
CVE-2024-11383
6.4 MEDIUM

The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cc-mortgage-canada' shortcode in all versions up to, and …

Jan 7, 2025
CVE-2024-11382
6.4 MEDIUM

The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 7, 2025
CVE-2024-11378
6.1 MEDIUM

The Bizapp for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' parameter in all versions up to, and including, 2.0.8 …

Jan 7, 2025
CVE-2024-11377
6.1 MEDIUM

The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and …

Jan 7, 2025
CVE-2024-11375
6.1 MEDIUM

The WC1C plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Jan 7, 2025
CVE-2024-11363
6.1 MEDIUM

The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & …

Jan 7, 2025
CVE-2024-11338
6.4 MEDIUM

The PIXNET Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtm' and 'venue' parameters in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11337
6.4 MEDIUM

The Horoscope And Tarot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'divine_horoscope' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11290
5.3 MEDIUM

The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the WordPress core search …

Jan 7, 2025
CVE-2024-10527
3.1 LOW

The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions …

Jan 7, 2025
CVE-2024-12592
6.4 MEDIUM

The Sellsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testSellsy' shortcode in all versions up to, and including, 2.3.3 due …

Jan 7, 2025
CVE-2024-12590
6.4 MEDIUM

The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.9 …

Jan 7, 2025
CVE-2024-12559
5.3 MEDIUM

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions …

Jan 7, 2025
CVE-2024-12557
6.1 MEDIUM

The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing nonce …

Jan 7, 2025
CVE-2024-12541
5.4 MEDIUM

The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is …

Jan 7, 2025
CVE-2024-12538
4.3 MEDIUM

The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.5 …

Jan 7, 2025
CVE-2024-12528
6.4 MEDIUM

The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 7, 2025
CVE-2024-12419
6.5 MEDIUM

The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrary shortcode execution in all …

Jan 7, 2025
CVE-2024-12416
7.5 HIGH

The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woomotiv_seen_products_.*' cookie in all versions up to, …

Jan 7, 2025
CVE-2024-12402
9.8 CRITICAL

The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover in …

Jan 7, 2025
CVE-2024-12098
6.1 MEDIUM

The ARS Affiliate Page Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'utm_keyword' parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11934
6.4 MEDIUM

The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'formaloo' shortcode in …

Jan 7, 2025
CVE-2024-11899
6.4 MEDIUM

The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11777
6.4 MEDIUM

The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_form_gutenberg' shortcode in all versions up to, and including, 2.5.8.5 …

Jan 7, 2025
CVE-2024-11437
4.9 MEDIUM

The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and including, 1.4 due to …

Jan 7, 2025
CVE-2025-22395
8.2 HIGH

Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading …

Jan 7, 2025
CVE-2025-21620
7.5 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. When you send a request with the Authorization header to one domain, and the …

Jan 6, 2025
CVE-2024-55553
7.5 HIGH

In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal …

Jan 6, 2025
CVE-2024-54767
7.5 HIGH

An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is …

Jan 6, 2025
CVE-2024-54764
6.5 MEDIUM

An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Jan 6, 2025
CVE-2025-21616
5.4 MEDIUM

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated …

Jan 6, 2025
CVE-2024-54763
6.5 MEDIUM

An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Jan 6, 2025
CVE-2024-53936
6.3 MEDIUM

The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user …

Jan 6, 2025
CVE-2024-53935
6.5 MEDIUM

The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables any application (with no permissions) to place phone calls without …

Jan 6, 2025
CVE-2024-53934
7.7 HIGH

The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls without user …

Jan 6, 2025
CVE-2024-53933
6.3 MEDIUM

The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Android enables any application (with no permissions) to place phone calls without …

Jan 6, 2025
CVE-2024-53932
9.1 CRITICAL

The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any application (with no permissions) to place phone calls without user …

Jan 6, 2025
CVE-2024-53931
9.1 CRITICAL

The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without user …

Jan 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.